Entry points have been observed being attacked across multiple open-source environments with an aim towards launching supply chain attacks.In an Oct. 14 blog post, Checkmarx researchers explained that attackers can exploit entry points to launch malicious code across the following environments: PyPI (Python), npm (JavaScript), Ruby Gems, NuGet (.Net), Dart Pub, and Rust Crates.One of the main attack methods includes command-jacking, which is what the researchers describe as impersonating popular third-party tools and system command and then targeting various stages of the development process via malicious plug-ins and extensions. The researchers said the entry-point attacks offer bad actors a more stealthy and persistent method of compromising system environments because it lets them bypass traditional security checks.In ecosystems such as PyPI, npm, and Rust Crates, Jason Soroko, senior fellow at Sectigo, said such attacks are a powerful way to introduce malicious code into developer workflows and CI/CD pipelines, bypassing standard security controls.
Network Security, DevSecOps, Supply chain![(Adobe Stock)](https://image-optimizer.cyberriskalliance.com/unsafe/1920x0/https://files.cyberriskalliance.com/wp-content/uploads/2024/10/101424_digital_chain.jpg)
Command-jacking used to launch malicious code on open-source platforms
![(Adobe Stock)](https://image-optimizer.cyberriskalliance.com/unsafe/1920x0/https://files.cyberriskalliance.com/wp-content/uploads/2024/10/101424_digital_chain.jpg)
(Adobe Stock)
An In-Depth Guide to Network Security
Get essential knowledge and practical strategies to fortify your network security.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds